Database/Control plane, storage & DevOps

Nagios Log Server: group-writable sudo scripts let the web user replace a root script and get root
Impact
The www-data user that runs the Log Server web application is in the nagios group, which has write access to /usr/local/nagioslogserver/scripts, while several root-owned scripts in that directory are runnable through sudo with no password. Anyone executing as www-data can move a root-owned script aside, drop a replacement at the same path, and invoke it under sudo for arbitrary root command execution - full compromise of the appliance OS. For an operator that means any web-tier bug in the log server, or any shell as the web user, becomes root on the box that holds the fleet's aggregated logs: audit trail tampering, credentials for the systems it polls, and a trusted pivot into the management network.
Who can reach it
Local code execution as www-data on the Log Server host - typically chained from a web-application flaw or from any existing low-privileged shell. No password or sudo credential is needed; the sudo rules are passwordless. Not exploitable by an unauthenticated remote attacker on its own.
What to do
Upgrade to Nagios Log Server 2026R1.0.1 or later, which is the vendor fix, and restart the appliance services; the upgrade is an in-place package update rather than a reboot. If an upgrade cannot be scheduled immediately, remove the nagios group's write permission on /usr/local/nagioslogserver/scripts and narrow the passwordless sudo rules that point into that directory.
References
Related entries
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsCVE-2025-41250 · VMware vCenter (SMTP header injection via scheduled tasks)High
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areCVE-2025-61972 · AMD NBIO register lock bits - System Management Network accessHigh
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredCVE-2026-0207 · Pure Storage FlashBlade loggingHigh
- GitLab package registry: authenticated path traversal that can lead to remote code executionCVE-2026-10053 · GitLab CE/EE package registryHigh
- GitLab: developer-role user can run pipelines on a protected branch without push rightsCVE-2026-15423 · GitLab CE/EE (CI/CD pipeline reference authorization)High
- GitLab EE: authenticated user can attribute AI usage to another namespaceCVE-2026-19228 · GitLab EE (AI feature usage attribution / request identity authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.